'\" te
.\" Copyright (c) 2003, Sun Microsystems, Inc. All Rights Reserved
.\" The contents of this file are subject to the terms of the Common Development and Distribution License (the "License").  You may not use this file except in compliance with the License.
.\" You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE or http://www.opensolaris.org/os/licensing.  See the License for the specific language governing permissions and limitations under the License.
.\" When distributing Covered Code, include this CDDL HEADER in each file and include the License file at usr/src/OPENSOLARIS.LICENSE.  If applicable, add the following below this CDDL HEADER, with the fields enclosed by brackets "[]" replaced with your own identifying information: Portions Copyright [yyyy] [name of copyright owner]
.TH KPROPLOG 8 "Oct 29, 2015"
.SH NAME
kproplog \- display the contents of the Kerberos principal update log
.SH SYNOPSIS
.LP
.nf
\fB/usr/sbin/kproplog\fR [\fB-h\fR | \fB-e\fR \fInum\fR]
.fi

.SH DESCRIPTION
.sp
.LP
The \fBkproplog\fR displays the contents of the Kerberos principal update log
to standard output. This command can be used to keep track of the incremental
updates to the principal database, which is enabled by default. The
\fB/var/krb5/principal.ulog\fR file contains the update log maintained by the
\fBkadmind\fR(8) process on the master KDC server and the \fBkpropd\fR(8)
process on the slave KDC servers. When updates occur, they are logged to this
file. Subsequently any KDC slave configured for incremental updates will
request the current data from the master KDC and update their
\fBprincipal.ulog\fR file with any updates returned.
.sp
.LP
The \fBkproplog\fR command can only be run on a KDC server by someone with
privileges comparable to the superuser. It will display update entries for that
server only.
.sp
.LP
If no options are specified, the summary of the update log is displayed. If
invoked on the master, all of the update entries are also displayed. When
invoked on a slave KDC server, only a summary of the updates are displayed,
which includes the serial number of the last update received and the associated
time stamp of the last update.
.SH OPTIONS
.sp
.LP
The following options are supported:
.sp
.ne 2
.na
\fB\fB-h\fR\fR
.ad
.RS 11n
Display a summary of the update log. This information includes the database
version number, state of the database, the number of updates in the log, the
time stamp of the first and last update, and the version number of the first
and last update entry.
.RE

.sp
.ne 2
.na
\fB\fB-e\fR\ \fInum\fR\fR
.ad
.RS 11n
Display the last \fInum\fR update entries in the log. This is useful when
debugging synchronization between KDC servers.
.RE

.sp
.ne 2
.na
\fB\fB-v\fR\fR
.ad
.RS 11n
Display individual attributes per update. An example of the output generated
for one entry:
.sp
.in +2
.nf
Update Entry
    Update serial # : 4
    Update operation : Add
    Update principal : test@EXAMPLE.COM
    Update size : 424
    Update committed : True
    Update time stamp : Fri Feb 20 23:37:42 2004
    Attributes changed : 6
          Principal
          Key data
          Password last changed
          Modifying principal
          Modification time
          TL data
.fi
.in -2

.RE

.SH FILES
.sp
.ne 2
.na
\fB\fB/var/krb5/principal.ulog\fR\fR
.ad
.RS 28n
The update log file for incremental propagation.
.RE

.SH ATTRIBUTES
.sp
.LP
See \fBattributes\fR(7) for descriptions of the following attributes:
.sp

.sp
.TS
box;
c | c
l | l .
ATTRIBUTE TYPE	ATTRIBUTE VALUE
_
Interface Stability	Evolving
.TE

.SH SEE ALSO
.sp
.LP
.BR kpasswd (1),
.BR kadm5.acl (5),
.BR kdc.conf (5),
.BR attributes (7),
.BR kerberos (7),
.BR kadmin (8),
.BR kadmind (8),
.BR kdb5_util (8),
.BR kprop (8),
.BR kpropd (8)
